6 ms·
The bug was part of the IME’s built in HTTP server, which is what the parent was alluding to.
by flafla2 8y ago
The bug was part of the IME’s built in HTTP server, which is what the parent was alluding to.
- ajross 8y agoSure, but that's "in our CPUs" in, kinda, exactly the same way that nginx is. It's a microcontroller. It's not like the hardware implemented an HTTP server.
- exikyut 8y agoIf I just swap the paragraphs in your comment, > It's not like the hardware implemented an HTTP server. But yes, yes yes it is. I don't mean "in our CPUs" in the sense of running nginx. I say "in our CPUs" because - the Web server is physically inside the CPU die - you can't remove or change it thanks to code signing, so (to me) it's truly wedged in there In effect, it's as hardcoded as the electrical circuitry and the transistors are. Andrew Tannenbaum penned an open letter of surprise and shock because the use of MINIX was an implementation detail ("the licensing works for us, and it's been stared at by tons of professors and a bunch of smart kids for about 20 years, it's good"). Okay, so it's running on 3 little 486-and-a-bit class x86 cores, and it isn't embedded into the main execution pipelines (...yet. I can see that being attractive, something something "software defined ICE"). These details don't change the bigger picture - until someone can break the ME signing infra in a way Intel can't easily fix, and we can disable (or, more ideally, take over/pwn) ME for good, it's as good as mask ROM.
- ajross 8y ago> - the Web server is physically inside the CPU die It's loaded from external storage, and probably runs in external DRAM. > - you can't remove or change it thanks to code signing, so (to me) it's truly wedged in there They literally just did, that's what the linked article is about. > In effect, it's as hardcoded as the electrical circuitry and the transistors are. If your criteria for hyperbole is the inability of the user to make modifications, then every effective DRM strategy is "as hardcoded as the electrical circuitry and transistors" also. That's silly. It's a CPU. It runs software. It speaks to devices with drivers. There's no technical meat to your argument.
- exikyut 8y ago>> - the Web server is physically inside the CPU die > It's loaded from external storage No, it's stored on NAND located physically inside the CPU. > , and probably runs in external DRAM. It can access all of main memory (and actively uses this ability as part of operations, probably for MMIO communications with UEFI and SMM), but I do think the little 486+-class cores have a bit of their own dedicated RAM on-chip. This makes sense; you don't want MINIX's operation interfering with whatever OS is running, and besides, if you did use main RAM, masking the used pages (with the MMU), so the OS couldn't simply observe/control everything, would honestly leave too much of a visible dent in the system and probably make more of a stink. >> - you can't remove or change it thanks to code signing, so (to me) it's truly wedged in there > They literally just did, that's what the linked article is about. Right. Now to wait and see how long this jailbreak lasts for... >> In effect, it's as hardcoded as the electrical circuitry and the transistors are. > If your criteria for hyperbole is the inability of the user to make modifications, then every effective DRM strategy is "as hardcoded as the electrical circuitry and transistors" also. I'm taking into account the specifics of this particular scenario. I'm aware of other context, but in this case I'm not generalizing. ME updates are signed, and there's currently no complete "perfect" jailbreak, so the effective summarization is "it's locked down". Considering the specifics of other DRM implementations, well, my favorite DRM is WideVine, since that runs on Linux, there's nothing like HDCP for audio yet, so... https://news.ycombinator.com/item?id=15796420 https://news.ycombinator.com/item?id=15796420 :D - but see all the replies :(, some DRM is indeed that locked down in practice, with no straightforward recourse. > That's silly. It's a CPU. It runs software. It speaks to devices with drivers. There's no technical meat to your argument. Technically you're right, for a strict/narrow definition of "CPU" that describes an abstract bridge between a perfect software environment and the squishy/vague real world. I'm not using that definition. I'm also not looking at Intel products as CPUs here (or, okay, not just CPUs), but as devices that contain a component I literally cannot control, with the exception of some vulnerability PoC code that's already been patched. The established status quo is that I cannot own this part of my hardware, that I'm buying the physical package but relinquishing [control over] some aspect[s] of its operation[s] to the manufacturer['s agenda]. The ME runs Minix, which does use drivers, sure. But that's back to looking at hardware exclusively from the software side of things, which is not the basis of this argument.